sync

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to read and follow instructions from an external file located at node_modules/@notionhq/apps/skills/sync/SKILL.md. This creates a surface where instructions from a project dependency are ingested into the agent context.
  • Ingestion points: The local file system path node_modules/@notionhq/apps/skills/sync/SKILL.md.
  • Boundary markers: None are defined in the skill body to delimit or sanitize the external instructions.
  • Capability inventory: The skill itself does not define any tools, subprocess calls, or network operations.
  • Sanitization: No sanitization or validation of the external file's content is performed.
  • [NO_CODE]: The skill consists exclusively of markdown instructions and metadata. It does not include any scripts, binaries, or executable code, relying instead on existing project dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:37 AM
Security Audit — agent-trust-hub — sync